Cross-site scripting in eLabFTW - #VU137350
Published: July 12, 2026
Vulnerability details
The vulnerability allows a remote user to inject arbitrary html into notifications.
The vulnerability exists due to cross-site scripting in the notification dropdown when rendering the profile fullname from action-request notifications. A remote user can update their profile fullname via the user profile API and trigger an action-request notification to inject arbitrary html into notifications.
User interaction is required for another authenticated user to view the notification dropdown.